CVE-2023-28002

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
14/11/2023
Last modified:
18/10/2024

Description

An improper validation of integrity check value vulnerability [CWE-354] in FortiOS 7.2.0 through 7.2.3, 7.0.0 through 7.0.12, 6.4 all versions, 6.2 all versions, 6.0 all versions and VMs may allow a local attacker with admin privileges to boot a malicious image on the device and bypass the filesystem integrity check in place.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:* 2.0.0 (including) 2.0.13 (including)
cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:* 7.0.0 (including) 7.0.13 (including)
cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:* 7.2.0 (including) 7.2.7 (including)
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* 6.0.0 (including) 6.0.17 (including)
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* 6.2.0 (including) 6.2.15 (including)
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* 6.4.0 (including) 6.4.14 (including)
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* 7.0.0 (including) 7.0.12 (including)
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* 7.2.0 (including) 7.2.3 (including)


References to Advisories, Solutions, and Tools